logo

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

ID: a426a8c9-d409-502d-aefe-f98a4c0a9d32

STIX ID: report--a426a8c9-d409-502d-aefe-f98a4c0a9d32

Feed Name: The Hacker News

Threat Score
82/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: [email protected] (The Hacker News)

...
...

**UAT-10147 campaign**: Researchers attribute a large-scale, Chinese-speaking cybercrime campaign to UAT-10147 that uses publicly disclosed vulnerabilities and AI-assisted tooling to compromise Windows and Linux web servers across multiple sectors and countries, deploy web shells and implants (BadIIS, Quasar RAT, Gh0stCringe, Noodle RAT) and a new cross-platform backdoor called SPECTRE which includes kernel-level rootkit and EDR-bypass capabilities, enabling persistent data theft and SEO fraud from an exposed target list of roughly 170,000 URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.